# Which cloud directory provider has the best security and compliance features for a healthcare organization that has strict access control requirements?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">To work out which cloud directory provider has the best security and compliance features for a healthcare organization that has strict access control requirements, I went past the marketing pages and filtered <a class="a a--md" elv="true" href="https://www.g2.com/categories/cloud-directory-services">cloud directory services</a> reviews down to reviewers in hospital and health care organizations. Interesting finding first: even healthcare reviewers rarely name HIPAA in their reviews. What they praise instead is the plumbing that makes strict access control livable day to day, which is probably the more useful signal anyway. What the healthcare-filtered set shows:</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/okta/reviews"><strong>Okta</strong></a>: One theme from healthcare reviewers is securely signing into shared workstations across offices with phone-based verification as the only way in, which is exactly the shared-terminal reality of clinical environments. Adaptive access that evaluates location and device per login shows up in reviews as well.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/rippling-it/reviews"><strong>Rippling IT</strong></a>: The deepest healthcare review base in this category's top products over the past year. Healthcare admins describe onboarding going from complicated and disorganized to nearly effortless, which matters for access control because rushed manual provisioning is where over-permissioning starts.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/jumpcloud/reviews"><strong>JumpCloud</strong></a>: Healthcare reviewers echo the wider base: one point of control for MDM, SSO, and the user directory, reducing the tool sprawl of a hybrid workforce. Reviewers also note audit logs feeding compliance evidence collection, which auditors will ask for.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/aws-directory-service/reviews"><strong>AWS Directory Service</strong></a>: Amazon states SOC, PCI, HIPAA, and FedRAMP compliance for the service, a vendor claim worth validating in procurement. Its G2 review base is tiny at 17 reviews, so this one is here for architecture fit if your clinical workloads already run in AWS, not review depth.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/manageengine-admanager-plus/reviews"><strong>ManageEngine ADManager Plus</strong></a>: The vendor positions automated audit trails and access reviews supporting GDPR and HIPAA frameworks, and its reviewer base skews toward regulated industries like banking and government. Vendor claim on the frameworks, review-backed on the reporting strength.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For anyone running one of these in a healthcare setting, what did your last access audit actually flag? And is anyone enforcing different MFA rules for clinical versus back-office staff?</p>

##### Post Metadata
- Posted at: 3 months ago
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;The shared-workstation comments point to another healthcare-specific test: how quickly access disappears when someone changes roles, locations, or employment status. Strong authentication protects the login, but stale privileges can survive behind it. I’d want to test whether role changes propagate cleanly across connected clinical systems or whether access reviews still uncover accounts that should have been removed weeks earlier.&lt;/p&gt;

##### Comment Metadata
- Posted at: 9 days ago
- Author title: Writer



### Comment 2

&lt;p&gt;&lt;span style=&quot;background-color: transparent; color: rgb(0, 0, 0);&quot;&gt;We run different MFA rules for clinical versus back-office staff, phone-based verification for shared clinical workstations and a stricter adaptive policy for admin accounts. Okta&#39;s adaptive access evaluating location and device per login made it straightforward to keep those two policies separate without maintaining two different systems.&lt;/span&gt;&lt;/p&gt;

##### Comment Metadata
- Posted at: 11 days ago
- Author title: SEO Content Writer



### Comment 3

&lt;p&gt;Access audits tend to expose stale or overly broad permissions, so I’d want provisioning and offboarding to be tightly controlled. I’d also enforce different MFA policies for clinical and back-office staff since their devices and access patterns can be very different. Okta’s adaptive access approach sounds particularly useful for making those distinctions.&lt;/p&gt;

##### Comment Metadata
- Posted at: 12 days ago



### Comment 4

&lt;p&gt;&lt;span style=&quot;background-color: transparent; color: rgb(0, 0, 0);&quot;&gt;The HIPAA-in-reviews finding is surprising but makes sense, what healthcare IT actually needs day-to-day is &quot;can I lock this shared workstation quickly,&quot; not a compliance certification on a slide.&lt;/span&gt;&lt;/p&gt;

##### Comment Metadata
- Posted at: 2 months ago
- Author title: Marketing Executive





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


